In recent months, children’s online safety and privacy have moved to the top of the EU’s digital agenda. The European Commission is expected to outline its proposal on minors’ access to social media this week, a potentially significant development that would build on the recommendations of the Commission’s Special Panel on child safety online and mounting pressure from Member States.
The EU is not moving in isolation. Similar debates on minors’ access to online platforms, age assurance, and safety-by-design obligations are emerging in other jurisdictions. These include Australia and the United Kingdom, as well as a rapidly developing patchwork of state-level age-verification, app-store, and device-based age-assurance requirements in the United States.
This post provides a horizon-scanning update on the principal regulatory developments at the EU level, selected national developments, and some relevant developments outside the EU.
I. Key EU Developments
A. EU Proposals: Minors’ Access to Social Media and the Digital Fairness Act
At the EU level, attention has increasingly focused on the possible introduction of an EU-wide minimum age for social media. On July 13, the Commission’s Special Panel on child safety online recommended a developmental, age-tiered framework structured around three developmental stages: (i) avoid screens for toddlers (under the age of 3), (ii) supervised, age-appropriate use for children between 3-12 years of age, and (iii) “evolving autonomous use” with mandatory safety features for those between 13-18 years of age. The Special Panel Report recommended that, “[u]ntil they demonstrate that their services are safe by design, social media and other digital services providers should have restricted access to children under the age of 13 in the EU,” while noting that Member States could introduce additional precautionary restrictions for older adolescents. President von der Leyen welcomed the recommended “phased and gradual access” model and confirmed a legislative proposal would be released by the end of the year, with details expected in her State of the Union speech on September 16, 2026.
That proposal may be brought forward alongside, or potentially as part of, the Digital Fairness Act (“DFA”) proposal, which remains on track for Q4 2026. Among other things, the DFA proposal is expected to address personalized advertising directed at minors, influencer marketing, age assurance measures, default safety and privacy settings for children, and platform design features that may contribute to excessive or compulsive use by minors. If minors’ access is folded into the DFA, a consumer-protection law, that would likely mean consumer protection authorities will be tasked with enforcement, which would occur alongside the ongoing work of Digital Services Coordinators (“DSCs”) pursuant to the Digital Services Act (“DSA”), which also contains restrictions designed to protect children on DSA-regulated platforms.
B. Digital Services Act Enforcement Focus on Minors
For the past several months, the European Commission’s DSA enforcement activity has increasingly focused on the protection of minors online, including issues relating to age assurance, recommender systems, default settings for minors, and features sometimes described as having an “addictive or manipulative design.” This enforcement activity suggests a broader focus on child-safety obligations under Article 28 DSA and core platform design choices, rather than transparency obligations alone.
The Commission’s 2025 Guidelines provide a useful benchmark for platforms accessible to minors to assess compliance with Article 28(1) of the DSA. Recommended measures include private-by-default accounts, adjusted recommender systems, disabling “addictive design” features by default, and the use of proportionate age-assurance methods, including age verification where a national minimum-age rule applies.
C. EU Age Verification and Age Assurance Initiatives
These recent developments have brought increased attention to age-assurance measures and their associated data protection implications. In February 2025, the European Data Protection Board (“EDPB”) adopted a statement on age assurance, setting out ten principles for the compliant processing of personal data when verifying or estimating a user’s age. The EDPB emphasized that methods should be as minimally intrusive as possible while remaining effective, and that children’s data must be protected throughout.
In parallel, the European Commission is advancing several age-verification solutions. In April 2026, the Commission made available its own age verification solution that can be customized by Member States and market players. The European Commission’s accompanying Recommendation calls on Member States to make the EU age verification solution available by December 31, 2026, either as a standalone app or integrated into the European Digital Identity Wallet. It further encourages coordination among Member States, the Commission, national DSCs, researchers, and civil society. The Recommendation further called for an EU Age Verification Scheme to set common trust and governance requirements for providers, including EU-level lists of compliant solutions and trusted proof-of-age attestation providers. Consistent with that objective, the EU Age Verification Trusted List became available on July 10, 2026, on the eIDAS Dashboard.
D. Other Developments
The broader EU framework for protecting children online continues to evolve. In particular, the temporary derogation from certain provisions of the ePrivacy Directive, which allows certain communications services to undertake voluntary measures to detect, report, and remove online child sexual abuse material (“CSAM”), has been renewed following a short period of expiration. The renewed temporary framework applies until April 3, 2028, while negotiations on the proposed CSAM Regulation continue.
In addition, the Digital Omnibus on AI introduced new Article 5 prohibitions, applicable from December 2, 2026, on so-called “nudifier” tools and AI systems used to generate child sexual abuse material, reflecting a similar approach adopted in the UK and certain U.S. states.
Finally, the EDPB’s guidance pipeline is worth watching alongside the Commission’s. Its guidelines on children’s data are listed as a priority deliverable in the Board’s 2026-2027 Work Programme, and the minutes of the 121st plenary confirm that drafting is ongoing. This suggests that, as the Commission continues to advance its children’s safety agenda, the EDPB will add a further layer of guidance focused specifically on the protection of children’s personal data.
II. EU Member State-Level Initiatives
Several Member States have taken concrete steps to regulate minors’ access to certain online platforms, although the scope, legal basis, and regulatory model of these initiatives continue to vary significantly. For instance:
- Austria: In July 2026, the Austrian government proposed legislation restricting access by users under 14 to certain social media platforms. The draft measure would apply to platforms that rely on features such as recommendation algorithms, infinite scrolling and reward systems, while excluding certain interpersonal communication and messaging services. Entry into force currently envisaged for January 2027, with compliance required by March 31, 2027.
- France: In July 2026, the French Parliament approved legislation restricting social media access for users under 15, following amendments made in response to the Commission’s detailed opinion. Shortly thereafter, the French Constitutional Council blocked the law’s central provision, finding that an undifferentiated restriction applicable to a broad swath of platforms and all users under 15, without regard to platform-specific risks, the child’s age or maturity, or parental involvement, disproportionately interfered with freedom of expression. The Constitutional Council also found that the provision lacked adequate privacy safeguards for the age-verification checks that would have applied to all users, including adults. In response to the decision, the French government indicated that it would prepare a revised legislative proposal as quickly as possible. For more details, see our previous post here.
- Denmark: On September 7, 2026, the government launched a public consultation on a draft bill establishing a minimum age of 15 for social media platforms, with entry into force projected to occur on July 1, 2027.
Developments in other European jurisdictions, including Greece, Norway and Romania, also illustrate that national age thresholds remain popular legislative pursuits. However, the related verification, supervision, and enforcement mechanisms are not always aligned with the EU’s harmonised legal framework. In particular, their relationship to the DSA and e-Commerce Directive, including with respect to the country-of-origin principle and applicable notification requirements, is often unclear. More specifically:
- Greece: The Commission issued a detailed opinion on a Greek draft law requiring social-network providers to use “appropriate, proportionate and reliable age-verification methods” to prevent access by users under 15. It found that the prescribed age-verification and optional age-estimation methods would encroach on Article 28(1) DSA, which it considers fully harmonises providers’ age-assurance obligations, and that the proposed notification of suspected infringements by foreign-established platforms would overlap with the DSA’s cooperation mechanism. However, the Commission found no breach of the e-Commerce Directive’s country-of-origin principle because the measure applies generally to domestic and foreign providers.
- Norway: In relation to Norway’s proposed under-16 restriction, the Commission indicated that the proposed age threshold would not appear to conflict with Article 28 DSA to the extent that the measure is limited to protecting minors, but both the Commission and the EFTA Surveillance Authority raised potential country-of-origin concerns regarding obligations imposed on providers established outside Norway.
- Romania: In Romania, the national audiovisual regulator has similarly cautioned that proposed legislation aimed at strengthening protections for children under 15 online, including age verification requirements, parental consent mechanisms, restrictions on access to certain online services, and enhanced platform obligations relating to minors, may overlap with the DSA. The regulator recommended clearly distinguishing measures that supplement the EU framework from provisions that merely reproduce existing DSA obligations concerning the protection of minors online.
At the same time, data protection regulators continue to scrutinize the implications of various age assurance tools, given that several of them process personal data such as facial images and combined data across platforms. For example, in March 2026, the Spanish AEPD fined Yoti €950,000 in connection with its Digital ID app, alleging, among other things, that it processed biometric data without a valid Article 9 GDPR condition. As another example, the French data protection authority, the CNIL, has recommended age-verification systems based on independent third-party verification and “double anonymity,” whereby the age-verification provider does not know which service the user is accessing, and the service provider does not receive the user’s identity, to safeguard users’ privacy and personal data.
III. Developments Beyond the EU
Similar debates on minors’ access to online platforms, age assurance, and safety-by-design obligations are emerging in jurisdictions outside the EU, offering useful points of comparison as the EU framework develops. Notable developments in other jurisdictions include:
A. Australia
Australia was the first country to legislate a strict minimum age for social media, requiring social media platforms to take reasonable steps to prevent users under 16 from holding accounts. The enforcement of the Australian legislation is being closely monitored in the EU, particularly as policymakers assess the practical implications of minimum-age requirements and related age-assurance obligations.
B. Brazil
Brazil has emerged as one of the most active jurisdictions in this area following the adoption of the Digital Statute of the Child and Adolescent (“Digital ECA”), which entered into force in March 2026. The legislation establishes a comprehensive framework for digital products and services directed at, or likely to be accessed by, children and adolescents, incorporating concepts such as safety-by-design, privacy-by-design, parental supervision tools, age-assurance measures, and restrictions on certain design practices considered harmful to minors. The law also places significant emphasis on the “best interests” of children and adolescents and requires providers to assess and mitigate risks to minors in the digital environment.
Public debate has intensified following several high-profile online safety incidents involving minors. The Brazilian National Data Protection Agency (“ANPD”)—which also serves as the data protection regulator under Brazil’s General Personal Data Protection Law (“LGPD”)—is now increasing Digital ECA enforcement by pursuing both company-specific investigations and collective oversight. On August 21, ANPD issued requests for information in connection with 22 digital platforms, app stores, and GenAI models, in an effort to assess those companies’ compliance with the new law.
C. Malaysia
Malaysia’s Child Protection Code, adopted under the Online Safety Act 2025, took effect on June 1, 2026. The Code prohibits users under 16 from registering social media accounts and requires licensed platforms with at least eight million users in Malaysia to verify users’ ages using government-issued identification, rather than relying on self-declaration. Existing accounts held by users under 16 are also subject to verification and may be suspended following a grace period. The obligations apply to platforms rather than parents or children. Gaming and communications services are not currently classified as social media and therefore fall outside the Code’s scope.
D. United Kingdom
The United Kingdom has opted for a more granular regulatory model as it continues to layer on top of the Online Safety Act 2023 (“OSA”) and the Information Commissioner’s Office (“ICO”) Children’s Code. Two new enabling acts that received royal assent in April—the Children’s Wellbeing and Schools Act 2026 and the Crime and Policing Act 2026—introduced several new powers and requirements, including the ability of the Secretary of State to restrict children’s access to specified services or functionalities and new offenses related to nudification tools, non-consensual intimate imagery, and related conduct.
With these new powers, the government announced in June a ban on social media for under-16s and, in July, functionality restrictions such as default midnight-to-6 a.m. curfews, restricted autoplay and personalized feeds for 16-17 year-olds, and mandatory chatbot breaks for under-18s.
Meanwhile, Ofcom launched the third phase of its implementation of the OSA by releasing its Register of Categorised Services and a series of consultations, including on a draft Category 1 Additional Duties Code covering user empowerment, optional identity verification, and safeguards for news, journalistic, and democratic content (for more details, see here). In May, it also confirmed its “hash matching” recommendation for its Illegal Content Codes to combat intimate image abuse, while the government worked with device manufacturers to block access to nude images on devices such as smartphones.
The ICO has also increased its scrutiny of children’s data protection (and, in particular, age assurance) under the Children’s Code and the UK GDPR. In addition to ongoing enforcement activity, in an August 2026 progress update regarding the UK Children’s Code the ICO reported that it was continuing its engagement with major online platforms and had launched a series of risk reviews of 14 age assurance providers, in which it found both areas of good practice and areas that need improvement. In addition, in March, the ICO and Ofcom issued a joint statement on age assurance, emphasizing that age-assurance measures must be both highly effective and compliant with data protection requirements, and that providers should adopt approaches that are proportionate to the risks posed by their services. The joint statement also provided some helpful insights into which forms of age assurance are and are not likely to be effective (for more details, see our blog here).
E. United States
For more details on recent developments in the U.S., see our blogs here and here.
IV. Looking Ahead
At minimum, the following key developments should be monitored closely over the next several months:
- The European Commission’s expected proposal on minors’ access to social media, due later in 2026.
- Increasing enforcement under the EU Digital Services Act focused on minors’ safety, recommender systems, and so-called “addictive design” features.
- The rollout of EU age-verification solutions and related age-assurance requirements.
- National initiatives, particularly in France and Austria, which may shape or influence future EU legislation.
- The European Commission’s forthcoming Digital Fairness Act, which is expected to address digital marketing to minors and other online practices affecting children and consumers.
- Developments outside the EU, including enforcement of Brazil’s newly operational Digital ECA, additional safety regulations and details regarding the under-16 social media ban in the UK, and continued U.S. state-level activity.
- Regulatory overlaps, particularly as safety and privacy regulators pursue infringements arising from the same underlying facts under different legal frameworks.
***
The Covington team is closely monitoring these developments and is well placed to help clients assess their practical implications. Please reach out to a member of the team to discuss how they may affect your organization.